CVE-2025-54833
Opexustech Foiaxpress Public Access Link 11.1.0 – 11.12.3.0
Raw vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2025-54833 is a medium-severity Improper Restriction of Excessive Authentication Attempts (CWE-307) vulnerability in Opexustech Foiaxpress Public Access Link. Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Brute Force (T1110); ranked at the 42th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-25 (Reference Monitor) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-23291
Vulnerability Data
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 2 hardening rules · 1 OS baseline
V10.7.1V2.2.2V8.3.1V10.4.1
Mitigating Controls (NIST 800-53 r5) AI
Requires a tamper-proof, always-invoked reference monitor that cannot be bypassed by client-side logic.
Enforces all access decisions on the server according to policy rather than trusting client-supplied enforcement.
AC-7 directly enforces limits on consecutive failed logons, structurally blocking brute-force exploitation of the weakness.
Enforces information-flow rules at the server boundary instead of delegating them to the client.
Monitors and controls all external and key internal interfaces so that server-side policy cannot be off-loaded to clients.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Authentication enforcement directly includes lockout, throttling, and MFA policies that prevent brute-force attempts.
Secure SDLC practices directly prevent design flaws that place server security enforcement on the client.
Behavioral monitoring of authentication activity can detect excessive failed attempts after they occur.
Proper policy-based enforcement of authorizations implies server-side controls rather than client-only checks.
Generating auth logs enables later detection or forensics but does not itself restrict attempts.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure architecture principles discourage client-side trust but do not directly address this weakness.
Security testing can detect client-side enforcement but is not the primary mitigation.
Information access restriction is undermined when the client is trusted to enforce it.
Secure development lifecycle mandates server-side validation and prevents reliance on client enforcement.
Application security requirements explicitly call for server-side enforcement of security mechanisms.
Secure coding standards require server-side checks and reject client-only enforcement.
Hardening callouts derived
Configuration rules from DISA STIG baselines that bear on weaknesses of the type cited by this CVE. Each rule is shown with the relationship its mapping actually records, against the CWE it was authored against. Derived via CVE→CWE over `controls_xwalks` (authoritative rows only; rows rated `none` are excluded).
RHEL 7 (2 rules)
- V-204427 The Red Hat Enterprise Linux operating system must be configured to lock accounts for a minimum of 15 minutes after three unsuccessful logon attempts within a 15-minute timeframe. prevents CWE-307
- V-204428 The Red Hat Enterprise Linux operating system must lock the associated account after three unsuccessful root logon attempts are made within a 15-minute period. prevents CWE-307